CVE-2022-33872

CRITICAL

FortiTester <4.2.0 - Command Injection

Title source: llm
STIX 2.1

Description

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0397
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
fortinet/fortitester 2.3.0 - 3.9.2
Published Oct 18, 2022
Tracked Since Feb 18, 2026